Elevation of privilege
A compromised endpoint may grant actions beyond the caller role.
Control: Least Privilege
Master browser-only cybersecurity workflows across application vulnerability remediation, STRIDE threat modeling, least-privilege IAM, Zero Trust micro-perimeters, SOC incident containment, SIEM rule detection, software supply chains, and cloud compliance scoring.
Container & dependency scanners, OWASP Top 10 exploits, secrets management, and WAF hardening.
Stage progress
4 labs in scope
Simulate Trivy container image scans, Snyk SAST code analysis, and OWASP ZAP DAST web inspection. Identify CVEs, misconfigurations, and dependency risks before they reach production.
Select a scanner engine and target to begin vulnerability analysis.
| Finding ID | Severity | Scanner | Component | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-21626 | HIGH | Trivy | runc | 8.6 |
| CVE-2023-44487 | HIGH | Trivy | nghttp2 / Envoy | 7.5 |
| DEMO-SAST-001 | HIGH | Snyk Code | src/api/auth.ts:42 | — |
| CVE-2024-3094 | CRITICAL | Trivy | xz / liblzma | 10.0 |
| DEMO-DAST-001 | MEDIUM | OWASP ZAP | HTTPS response header | — |
| DEMO-SAST-002 | MEDIUM | Snyk Code | lodash | — |
| CVE-2023-38545 | CRITICAL | Trivy | libcurl | 9.8 |
| DEMO-DAST-002 | LOW | OWASP ZAP | /search?q= | — |
In runc 1.1.11 and earlier, a file-descriptor leak can give a container process access to the host filesystem in affected attack paths.
Select any OWASP Top 10:2025 category to inspect a display-only teaching scenario, compare vulnerable and remediated code, and identify the relevant defenses.
Failures allow unauthorized users to view, edit, or delete data belonging to other users (for example, IDOR and privilege escalation).
// VULNERABLE: Trusting a user-supplied ID without authorization
app.get('/api/invoice/:id', authMiddleware, async (req, res) => {
const invoice = await db.query('SELECT * FROM invoices WHERE id = $1', [req.params.id]);
res.json(invoice); // No ownership or role check
});// REMEDIATED: Enforce authorization for the authenticated principal
app.get('/api/invoice/:id', authMiddleware, async (req, res) => {
const invoice = await db.query(
'SELECT * FROM invoices WHERE id = $1 AND owner_id = $2',
[req.params.id, req.user.id]
);
if (!invoice) return res.status(404).json({ error: 'Not found' });
res.json(invoice);
});Compare provider-specific secret storage, dynamic credential leases, access policy, and rotation workflows. The controls below are a local simulation.
Storage & key protection: Encryption details depend on the configured Vault seal/storage and AWS KMS settings. Shamir shares protect an unseal workflow; AWS Secrets Manager uses KMS envelope encryption.
Configure illustrative request-filtering rules, compare TLS and HTTP-header settings, and inspect a local heuristic. A WAF is not a substitute for secure application code or dedicated DDoS protection.
| State | Rule Name | Type | Action | Blocked Hits |
|---|---|---|---|---|
| OWASP Core Rule Set - SQL Injection | SQLi | BLOCK | 1420 | |
| OWASP Core Rule Set - Cross Site Scripting (XSS) | XSS | BLOCK | 890 | |
| Rate Limit: Max 100 Reqs / 5 Min | RateLimit | BLOCK | 310 | |
| Geo-IP Filter: Block Tor Exit Nodes | GeoBlock | CAPTCHA | 145 |
Configure a local teaching heuristic for TLS and response headers; this is not an SSL Labs grade.
STRIDE threat modeling, least-privilege IAM policies, BOLA/IDOR API security, and Zero Trust boundaries.
Stage progress
4 labs in scope
Select an architecture asset, apply mitigations, and compare the remaining STRIDE findings against risk baselines.
Public request and application boundary
STRIDE threats ordered by severity.
A compromised endpoint may grant actions beyond the caller role.
Control: Least Privilege
An attacker may impersonate a caller when identity checks are weak.
Control: Strong Authentication
Untrusted request data can alter application state.
Control: Input Validation
Overly broad responses can expose data to unauthorized callers.
Control: Object Authorization
Unbounded requests can exhaust API capacity.
Control: Rate Limiting
Without an audit trail, actions cannot be reliably attributed.
Control: Audit Logging
Build an access request and evaluate it against local role policies, wildcard rules, and MFA condition blocks.
Deny rules are evaluated before matching Allow rules.
| Effect | Principal | Action | Resource | Condition |
|---|---|---|---|---|
| Deny | user/* | orders:Delete | orders/* | — |
| Allow | role/api-reader | orders:Get | orders/* | — |
| Allow | role/api-reader | orders:List | orders/* | — |
| Allow | role/ops-admin | admin:* | admin/* | MFA required |
| Allow | service/orders-worker | orders:Update | orders/prod | — |
| Allow | role/ops-admin | orders:* | orders/* | MFA required |
Test controls that protect an API boundary: identity, object ownership (BOLA), schema validation, and rate limits.
This illustrative request is display-only. The lab never executes entered payload text or sends network traffic.
GET /v1/orders/order_2048
Authorization: Bearer <short-lived-token>Model requests using identity, device posture, source zone, destination zone, MFA, and action under continuous verification.
Static policy stages make the trust boundary explicit before any decision is applied.
Every hop is evaluated with the same signals; being on a workforce or workload network does not grant implicit access.
SOC alert triage, incident containment, SIEM detection rules, and CycloneDX/SPDX SBOM audits.
Stage progress
3 labs in scope
Practice a repeatable incident lifecycle against safe, synthetic alerts: signal classification, forensic preservation, and containment.
Query synthetic authentication, API, WAF, and cloud audit events with correlation rules.
Inspect a synthetic package inventory for vulnerability flags, immutable versions, fixture provenance, and license policy before release.
The evaluator re-checks every row whenever the license policy changes.
| Package | Version | Severity | Fixture attestation | License |
|---|---|---|---|---|
| express | 4.19.2 | high | Signed | MIT |
| lodash | 4.17.21 | medium | Signed | Apache-2.0 |
| axios | ^1.7.2(unpinned) | low | Signed | MIT |
| internal-plugin | 2.1.0 | none | Unsigned | Apache-2.0 |
| legacy-parser | 1.4.0 | none | Signed | GPL-3.0 |
6 findings require attention before release.
Allowlist currently contains 2 of 3 licenses seen in the inventory.
Kubernetes pod security admission, multi-control cloud compliance scoring, and data classification.
Stage progress
3 labs in scope
Model a strict Kubernetes admission policy: non-root users, read-only root filesystems, and dropped Linux capabilities.
6 controls failed and must be remediated.
Container must run as a non-root user.
Remediation: Set a pod or image securityContext with runAsNonRoot: true and a non-zero runAsUser.
Container root filesystem must be read-only.
Remediation: Set securityContext.readOnlyRootFilesystem: true and mount explicit writable volumes where needed.
Host networking is not permitted.
Remediation: Remove hostNetwork: true and expose the service through a cluster Service or ingress.
Host path mounts are not permitted.
Remediation: Remove hostPath volumes and use an approved persistent volume or projected secret instead.
Image signature verification is required.
Remediation: Sign the image in CI and configure admission policy to verify its registry signature.
CPU and memory limits are required.
Remediation: Declare CPU and memory requests and limits in the workload specification.
Review a simulated AWS account snapshot across identity, storage, network, logging, and KMS controls.
Posture score
0
Grade F
Open findings
7
Evaluator-calculated risk
Resolved findings
0
Marked fixed locally
Last recalculation
Not run yet
Select a finding to inspect evidence and remediation.
| Control | Finding | Severity | Status |
|---|---|---|---|
| IAM | arn:aws:iam::000000000000:root | critical | |
| S3 | s3://acme-prod-invoices | high | |
| VPC | vpc-0f42a1e9 / subnet-07b3c4d1 | medium | |
| CloudTrail | arn:aws:cloudtrail:us-east-1:000000000000:trail/example-audit | high | |
| KMS | key/7e6d0d5c-4dcb-4ae5-9a19-prod-data | medium | |
| Security groups | sg-0a8d66bd / prod-postgres | critical | |
| IAM | user/example-deploy / EXAMPLE_KEY_ID | low |
Classify example data assets, inspect mapped protection controls, and complete a privacy readiness checklist.
Choose a field, then classify it according to its sensitivity and use.
| Field | Example value | Classification |
|---|---|---|
Link activity to a customer account | acct_7F29D1 | internal |
Send account notifications | alex@example.test | confidential |
Reference a vaulted payment method | tok_visa_••••4242 | restricted |
Display a catalog item | Network Fundamentals | public |
Use the checklist to turn classification into operating controls.